A man alone on a rooftop at dawn, reading his phone out of sight of the house

Security & trust

Protect responders whose safety depends on staying unidentified

In some places, being known as a Christian costs people their jobs, their families, or worse. That is not an edge case we designed around later. It is why several parts of Echo exist.

Schedule a demo Bring your security lead. Ask the hard questions out loud.

What Echo does

Protections, stated plainly

Security pages are usually a wall of badges. This one says what Echo does, in plain words, because a ministry making a safety decision deserves the real answer.

Between your team and the platforms

A wall between your responders and every platform

Seekers write on Messenger, WhatsApp, Instagram and the rest. Your responders answer inside Echo, and each reply goes back to the platform under your ministry’s name, not theirs.

Replies go out as your ministry. Echo sends each reply from your ministry’s own Page, account or number. Nothing Echo sends to Meta, WhatsApp or the other apps says which responder wrote it, and no responder signs in to those platforms to answer.

No Facebook account needed. A responder does not need a Facebook account to answer Messenger, or an Instagram account to answer Instagram. An admin connects each of your ministry’s accounts to Echo, and the whole team answers from there.

Calls and chat

Responders are not exposed

A call can ring on a responder’s own phone, but Echo places it and the ministry’s number is what the seeker sees.

Calls ring where the responder chooses. In the browser, or on a number of their own that Echo checks first by calling it. Either way Echo places its own call to the responder and joins it to the seeker’s, and when a responder calls a seeker back from Echo, your ministry’s number is what shows.

Chat shows a first name at most. On your website’s chat a seeker sees a responder’s first name, or the first name of their alias: a different name to use with seekers, which a responder can set for themselves and an admin can set for anyone. No conversation lives in a personal account, and when someone leaves the team the conversations stay with the ministry while their identity stays theirs.

Access

Access is locked down by default

Responders see the conversations they need and not the whole ministry. Who can see what is a decision your leadership makes, not a default we chose for you.

A permission set lists the sources a responder may see: chat pages, email accounts, phone numbers and social media accounts. A responder can only see conversations from those sources, so each person sees what they need and nothing more.

How permission sets work

Encryption

Encrypted in transit and at rest

Everything between your team’s browsers and Echo travels over an encrypted connection, and so do the messages Echo sends to Meta, WhatsApp and the other messaging platforms.

What Echo stores stays encrypted at rest, in a database that cannot be reached from the internet. Only Echo’s own servers can talk to it.

Sign-in

Two-factor sign-in, and you can require it

Any responder can turn on two-factor sign-in. After their password, Echo asks for a six-digit code, from an authenticator app or sent to their email.

An admin can require it for the whole team. Once it is required, nobody can switch it off for themselves.

The record

You can see what happened

Conversations carry their history. If you need to know who answered, when, and what was said, that is a question Echo can answer.

Kept current

Patched, updated and tested by us

Patched and updated, constantly

We patch and update Echo all the time to keep it secure.

Tested the way an attacker would

We try to break into Echo ourselves, to find weaknesses and close them.

The honest version

What we control, and what we do not

Echo runs on top of platforms we do not own. WhatsApp, Facebook, Instagram, TikTok, Telegram and the phone network all have their own rules, their own outages, and their own view of your data.

What we control

  • Who inside your ministry can see which conversations
  • How your responders reach people without exposing themselves
  • What Echo keeps, and what it shows in reporting

What we cannot

  • What a messaging platform itself retains about a conversation
  • Whether a platform is available in a given country this week
  • The device security of the person who reached out to you

Security questions

Asked by ministries in hard places

Echo was built with sensitive regions in mind: locked-down access, replies that go out under your ministry’s name, and two-factor sign-in you can require. Bring your security lead to the demo and ask them the hard questions. We would rather have that conversation early than sell you something that puts a responder at risk.

Each responder can have an alias, the name seekers see instead of their real one. A responder can set their own, and an admin can set or change anyone’s. On your website’s chat a seeker sees only the first name of it, and replies on Messenger, WhatsApp, SMS and the other messaging apps go out under your ministry’s name, with no responder’s name added. Walk through your exact situation on a demo.

Echo checks pictures as they arrive, using PicPurify, an image moderation service. One it flags as explicit is covered with a note, and a responder only opens it by choosing to. An admin can go further and hide or block all pictures, video and audio for the whole team.

This is exactly the kind of question that deserves a precise answer from our platform team rather than a comfortable one from a marketing page. Ask it on the demo and you will get it in writing.

Yes. It shows Echo apart from the partner platforms, because the two fail for different reasons and you need to know which one you are looking at.